CVE-2024-37086

MEDIUM

Vmware Cloud Foundation < 5.2 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.

Scores

CVSS v3 6.8
EPSS 0.0007
EPSS Percentile 21.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (3)
vmware/cloud_foundation 4.0 - 5.2
vmware/esxi 7.0 (27 CPE variants)
vmware/esxi 8.0 (14 CPE variants)
Published Jun 25, 2024
Tracked Since Feb 18, 2026